When you configure your DenyAll Web Application Firewall (WAF) to send log data to USM Appliance, you can use the DenyAll Web Application Firewall plugin to translate raw log data into normalized events for analysis. The table below provides some basic information for the plugin.
Device | Details |
---|---|
Vendor | DenyAll |
Device Type | Web Application Firewall |
Connection Type | Syslog |
Data Source Name | Denyall-waf |
Data Source ID | 1922 |
Integrating DenyAll WAF
Before you configure the DenyAll WAF integration, you must have the IP address of the USM Appliance Sensor.
To configure DenyAll WAF to send syslog messages to USM Appliance
- Log in to the DenyAll web UI.
- From the top menu, select Management > Alerting.
- From the left-side menu, select Alerting Profiles.
- Click Add and then enter the following information in the dialog box that appears:
- Facility: Select the facility to use to log messages.
- Host: Enter the USM Appliance IP Address.
- Name: Enter a name for the new alerting profile.
- Port: Enter 514.
- Protocol: Enter UDP.
- Severity: Select the desired severity level for messages to be returned.
- Type: Select Syslog.
- Click OK to close the dialog box.
- From the left-side menu, select Logs Alerting configurations.
- Click Add and then enter the following information into the dialog box that appears:
- Name: Enter a profile name.
- Frequency: Select the frequency of alert reporting.
- Format: Select Default.
- Destinations: Select <profile_name>(syslog).
- Ensure that Send security logs and Send IAM logs options are both selected.
- Click OK to close the dialog box.
Plugin Enablement
For plugin enablement information, see Enable Plugins.
Additional Resources and Troubleshooting
https://www.ubikasec.com/resources/glossary/
For troubleshooting, see the vendor documentation.